HP 4x1Ex32 HP IP Console Viewer User Guide - Page 42

Configuring authentication parameters, Parameter, Function, Virtual Media., Lock to KVM Session

Page 42 highlights

Parameter Encryption level Function This control can be used to specify the encryption method to use for all Virtual Media sessions. This information is used when new client connections are requested. At that point, the console switch will attempt to negotiate for the highest enabled encryption mechanism level. This setting is disabled by default. To configure these settings: 1. Select Virtual Media. 2. Enable or disable the checkboxes in the Session Control area. o If you clear the Lock to KVM Session option, your Virtual Media sessions can remain after the Video Session Viewer that launches the session closes. o If you select Allow Reserved Sessions, only the owner of the Virtual Media session can establish a KVM session to a reserved Virtual Media session. o If you select Read-Only Access, write access to Virtual Media sessions is prevented. 3. Select zero or more levels of encryption to encode Virtual Media data sent to the console switch in the Encryption Level area. The highest level enabled will be used. 4. Click Apply to save any changes without exiting. -orClick OK to save any changes and exit. -orClick Cancel to exit without saving any changes. Configuring authentication parameters The Authentication subcategory enables you to select the type of authentication method to be used. IMPORTANT: Before implementing LDAP functionality, see "HP IP Console Switch directory services integration setup tutorial (on page 276)" for a better understanding of how LDAP works. The three types of authentication are: • Local Authentication (with local access control) Provides secure managed switch based authentication, data transfers, and user name and password storage. With two levels of access control, Console Switch Administrator and User, you can set target server-specific access rights and inter-operate with existing firewalls, VPNs, and NAT-based networks. This is the default setting and has the same functionality as in the previous software release. • LDAP Authentication Only (with local ACL) Provides a secure managed directory-based authentication for passwords and user names and a local switch-based authorization for ACLs. ACLs are maintained and stored in each individual console switch. Passwords are only in the directory server. For more information on LDAP, see "Using directory services integration (on page 200)." • LDAP Authentication and Access Control Managing KVM console switches 42

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339

Managing KVM console switches
42
Parameter
Function
Encryption level
This control can be used to specify the encryption method to use for all Virtual
Media sessions. This information is used when new client connections are
requested. At that point, the console switch will attempt to negotiate for the highest
enabled encryption mechanism level. This setting is disabled by default.
To configure these settings:
1.
Select
Virtual Media.
2.
Enable or disable the checkboxes in the Session Control area.
o
If you clear the
Lock to KVM Session
option, your Virtual Media sessions can remain after the
Video Session Viewer that launches the session closes.
o
If you select
Allow Reserved Sessions,
only the owner of the Virtual Media session can establish a
KVM session to a reserved Virtual Media session.
o
If you select
Read-Only Access,
write access to Virtual Media sessions is prevented.
3.
Select zero or more levels of encryption to encode Virtual Media data sent to the console switch in
the Encryption Level area. The highest level enabled will be used.
4.
Click
Apply
to save any changes without exiting.
-or-
Click
OK
to save any changes and exit.
-or-
Click
Cancel
to exit without saving any changes.
Configuring authentication parameters
The Authentication subcategory enables you to select the type of authentication method to be used.
IMPORTANT:
Before implementing LDAP functionality, see "HP IP Console Switch directory
services integration setup tutorial (on page
276
)" for a better understanding of how LDAP
works.
The three types of authentication are:
Local Authentication (with local access control)
Provides secure managed switch based authentication, data transfers, and user name and password
storage. With two levels of access control, Console Switch Administrator and User, you can set
target server-specific access rights and inter-operate with existing firewalls, VPNs, and NAT-based
networks. This is the default setting and has the same functionality as in the previous software
release.
LDAP Authentication Only (with local ACL)
Provides a secure managed directory-based authentication for passwords and user names and a
local switch-based authorization for ACLs. ACLs are maintained and stored in each individual
console switch. Passwords are only in the directory server. For more information on LDAP, see
"Using directory services integration (on page
200
)."
LDAP Authentication and Access Control